I’d like to setup an LXD network for LXD containers such that all of its outgoing traffic is routed to an interface on the host system which is a Layer3 VPN. If this interface is down, no traffic should get out of the containers. I basically want to “seal” some containers under a VPN.
I tried a few things, for example creating a secondary bridge with:
lxc network create lxdvpn ipv4.address=none ipv6.address=none
but traffic still manages to get to the Internet, even if the
lxdvpn interface does not have an IP address on the host system! Apparently traffic is routed to
lxdbr0 and then to the default route. Do you have any hint?